SLMail Buffer Overflow 'helo' Vulnerability
BID:222
Info
SLMail Buffer Overflow 'helo' Vulnerability
| Bugtraq ID: | 222 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Feb 04 1999 12:00AM |
| Updated: | Feb 04 1999 12:00AM |
| Credit: | This vulnerability was posted to NTBugtraq by Marc <[email protected]>. |
| Vulnerable: |
Seattle Lab Software SLMail 3.0.2421 |
| Not Vulnerable: | |
Discussion
SLMail Buffer Overflow 'helo' Vulnerability
The POP Service of SLMail operates on tcp port 27. Issuing a 'helo' command followed by 855 to 2041 characters will cause the SLMail server to crash. An arbitrary command may be issued as a overflow exploit, although this is not discussed by the author of the post.
The POP Service of SLMail operates on tcp port 27. Issuing a 'helo' command followed by 855 to 2041 characters will cause the SLMail server to crash. An arbitrary command may be issued as a overflow exploit, although this is not discussed by the author of the post.
Exploit / POC
SLMail Buffer Overflow 'helo' Vulnerability
see discussion
see discussion
Solution / Fix
SLMail Buffer Overflow 'helo' Vulnerability
Solution:
Contact Seattle Labs (www.seattlelab.com) for a patch.
Solution:
Contact Seattle Labs (www.seattlelab.com) for a patch.
References
SLMail Buffer Overflow 'helo' Vulnerability
References:
References: